Legal
Privacy policy
Learn how Beanory handles accounts, baby profiles, growth records, and family sharing data.
Last updated: August 6, 2026
Beanory (“we,” “us,” or “our”) is a daily baby journal for parents and caregivers. This policy explains how we collect, use, store, share, and delete information when you use the Beanory app, account sync, family sharing, subscriptions, or this website. Our privacy contact is support@beanory.app.
1. Information we handle
We handle information needed to provide and protect the service, including:
- Account and sign-in information: the email address used for email-code sign-in, and identifiers, display name, and avatar returned by Apple or Google when you choose those sign-in methods. We do not require or receive a password, and we do not process your payment card number.
- Baby and household information: a baby’s name, birthday, gender, avatar, and household members, roles, invitation emails, and invitation status.
- Journal content: entries you create for breastfeeding, expressed milk, formula, sleep, waking, diapering, meals, snacks, bowel movements, medicine, baths, temperature, height, weight, head circumference, chest circumference, vaccines, milestones, moments, and other events, including times, amounts, notes, and names of medicines or foods.
- Photos and files: photos you attach to a baby profile or record and necessary file information such as format, dimensions, size, and checksum. Photos may contain identifiable information about a baby or family member.
- Device and security information: a device identifier, APNs push token, app version, language, sync cursor, and necessary operation logs. We may use an IP address for verification-code rate limiting, abuse prevention, and security auditing. The current version does not use advertising SDKs or cross-site behavioral tracking to build advertising profiles.
- Subscription information: Apple transaction and product identifiers, subscription status, expiration, auto-renewal status, and verification environment so we can validate Beanory Pro benefits. Apple processes payment information; we do not receive your full card number.
- Support information: the email address, issue description, screenshots, and other information you choose to send to support.
2. Sources, purposes, and legal bases
Information comes primarily from your entries, the Apple or Google sign-in service you select, your device, and your support requests. We use it to:
- create and protect accounts, send email codes, sign you in and out, manage sessions, and process account deletion;
- store baby profiles and records, generate statistics, trends, or growth reports, and provide local reminders, photo processing, cross-device sync, and family collaboration;
- process household invitations, member permissions, sync notifications, subscription verification, support requests, and troubleshooting; and
- prevent abuse, protect users and the service, comply with law, and establish or defend legal claims when necessary.
Depending on where you live, our legal bases may include performing the service you request, your consent, our legitimate interests in security and operations, and legal obligations. We request device permissions or other consent where required; you can turn off optional notifications in system settings.
3. On-device storage, sync, and family sharing
Before sign-in, baby profiles, records, some settings, and photos are primarily stored in the app’s local database and storage on the current device. After sign-in, information associated with your account and household that needs cross-device access or family sharing is synchronized to our backend. Sign-in credentials are stored in the iOS Keychain, and local photos use system file protection. What is synchronized depends on the sign-in, sync, and family features you use.
Members of the same household may see shared baby profiles, records, notes, and photos in that household. The household owner manages invitations and membership; invite only people you trust and remove or revoke access when it is no longer needed.
4. Health information, children’s information, and product boundaries
Feeding, sleep, temperature, height, weight, medicine, vaccine, and similar entries may be health-related information under applicable law and may concern a child. We use them only to provide the logging, statistics, sync, and sharing features you request. We do not use them for advertising, sale, cross-context behavioral advertising, profiling, or model training, and we do not provide medical diagnosis.
Beanory is intended for parents, guardians, and adult caregivers, not children. A parent or guardian should create and use the account and must ensure they have authority to enter, store, and share children’s information with household members. If you believe children’s information was submitted improperly, contact support@beanory.app.
5. Who we share information with
We do not sell personal information or share baby, health, or household records for targeted advertising. To operate the service, we may provide information as necessary to:
- Household members you authorize: only within the household space you join and its permitted members, for collaboration and sync.
- Apple: for Apple sign-in, App Store subscription payment and transaction verification, and APNs push infrastructure. Apple’s terms and privacy policy also apply.
- Google: for Google sign-in that you choose. Google’s terms and privacy policy also apply.
- Resend: to send email sign-in codes and household invitations.
- Cloud infrastructure providers: our API, PostgreSQL database, and Cloudflare R2 object storage host accounts, households, records, and photos. Photos are read through short-lived signed URLs; deleted photo objects may be retained for up to 30 days for sync and recovery workflows before cleanup.
- Legal, security, or transaction recipients: when required by law, needed to protect users or the service, resolve disputes, or support a merger, acquisition, financing, reorganization, or asset transfer.
6. International transfers
We and our service providers may process information outside your country or region. Where required, we use contractual, certification, adequacy, or other appropriate safeguards for international transfers. You may contact us for transfer information relevant to your request.
7. Retention, deletion, and account closure
We retain information for as long as needed to provide the service, meet legal obligations, resolve disputes, and enforce our agreements. Email verification challenges normally expire after 10 minutes. Sessions, device tokens, sync records, and subscription verification data are retained as needed for account operation, security, billing, and audit. We do not keep information indefinitely by default.
You can use the in-app account deletion flow or email us to request deletion. We will delete account identifiers, linked identities, sessions, device tokens, and data within the scope of your account from local and cloud storage. If you own a household, we will delete that household and its related babies, records, members, invitations, and subscription associations. If you are only a member, records maintained by the shared household for other members may remain, while your account and membership relationship are removed. Deleted photo objects may remain for up to 30 days for synchronization, recovery, and cleanup. Legal retention, backup media, and de-identified information may be exceptions.
8. Your rights and how to make a request
Depending on your location and applicable law, you may have rights to access or copy personal information, correct it, delete it, restrict or object to certain processing, request portability, withdraw consent, and receive information about our processing. Some U.S. state privacy laws may also provide rights to know, delete, correct, limit sensitive personal information use, and opt out of sale or sharing. Beanory currently does not sell personal information or share it for targeted advertising.
Send requests to support@beanory.app and include the request type and the account email involved. We may request reasonable identity verification to protect the account. We will respond within the time required by applicable law and explain an extension or refusal where needed. You may also complain to your local data protection or consumer protection authority.
9. Security
We use access controls, protected session credentials, verification-code rate limiting, encrypted transmission, signed photo URLs, database permissions, and iOS file protection to reduce risk. No device, network transmission, or cloud service is completely secure. Protect your device, account, and household invitations, and contact us promptly about suspected unauthorized access.
10. Changes to this policy
We may update this policy when features, laws, or service providers change and will update the date at the top of the page. We may notify you of material changes through the app, website, or another reasonable channel. Continued use means you have read the updated policy, except where the law requires fresh consent.